12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 8: Securing FOS-Based Fabrics<strong>Brocade</strong> switches are factory installed with four user accounts:• root• factory• admin• userFor the reasons described above, these accounts should never beused except as a last recourse when a SAN administrator's passwordis lost, for example, and there is no other way to gain access to theswitch. Each of these user accounts is also assigned a default passwordby <strong>Brocade</strong>. Some OEM partners change the <strong>Brocade</strong> defaultpassword to a different default password. As a best practice, changethese default passwords at first login.The password database is local to each switch. However, as of FOS5.2.0, it is possible to manually distribute the local password databaseto other switches in a fabric using the distribute command(distribute -p PWD -d switch_list). If for some reason youwant to exclude one or more switches from this distribution, use thefddCfg command entered from the switch to be excluded (fddCfg --localreject PWD).Password PoliciesA password policy can be created to ensure that users create strongpasswords and follow the organization's password policy. There arefour <strong>Brocade</strong> password policies that can be configured:• Password strength• Password history• Password expiration• Account lockoutImplement password policies on <strong>Brocade</strong> switches using the passwd-Cfg -set command.Password strength refers to how difficult it is for someone else toguess or break a user's password. A hacker often tries to guess a passwordusing real words such as a person's name, spouse's name, pet'sname, and so on. Real words should never be used as part of a passwordsince they are too easy to guess. The use of numbers, specialcharacters, and cases all contribute to making a password stronger.138 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!